Privacy statement
As at: 14 September 2026 · Version 2026-09-14 · German launch
This is a convenience translation. The binding version is the German Datenschutzerklärung.
This statement provides information pursuant to Art. 12 to 14 of the General Data Protection Regulation (GDPR) about the processing of personal data when using the BlickWinkel website, the shop, user accounts, email functions and the free digital card table.
1. Controller
Parlant GmbH
Gürtelstraße 25/Etage 4
10247 Berlin
Germany
Email: [email protected]
Authorised managing director: Lukas Rieder
No data protection officer has been appointed. Data protection enquiries can be sent to the email address above.
2. Which data we process
Depending on use, we process the following categories:
- Connection and security data: IP address, date and time, URL requested, referrer, HTTP status, browser and device data, technical identifiers, and security and error events.
- Session and visitor data: signed session identifier, pseudonymous visitor identifier, start and course of a browser session, and where applicable a device identifier.
- Website analytics data: page views, clicks, visible areas, interactions, technical timing values, source and target URL, and campaign parameters. We use our own self-hosted event capture for this and currently do not pass this data to advertising networks.
- Account and authentication data: email address, encrypted or hashed login tokens, account status, and times of login or confirmation.
- Digital card table data: session identifier, pseudonymous participant identifier, card positions, card selections, states and jointly triggered interactions. BlickWinkel does not record audio or video conversations.
- Order, contract and payment data: name, email, billing and delivery address, items ordered, price, currency, tax, shipping and return status, order number, and Stripe customer, checkout and payment identifiers. Parlant does not receive full card or bank details; these are processed by the payment service provider.
- Email and communication data: email address, double opt-in evidence, message content, dispatch and delivery status, and support, withdrawal, return and complaint correspondence.
The data generally originates from the data subject, their device, other participants in the same digital session, or the service providers used.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Deliver website and app securely, defend against attacks, fix errors | Art. 6 (1) (f) GDPR; legitimate interest in secure and stable operation |
| Provide the free digital card table, sessions and account functions | Art. 6 (1) (b) GDPR; performance of the free usage relationship |
| Evaluate reach and use pseudonymously, improve product and funnel | Art. 6 (1) (f) GDPR; legitimate interest in data-minimising, self-hosted website analytics |
| Initiate, pay for, deliver, withdraw from and complain about orders | Art. 6 (1) (b) GDPR |
| Meet commercial, tax, consumer and product safety requirements | Art. 6 (1) (c) GDPR |
| Send newsletters or availability notices after sign-up | Art. 6 (1) (a) GDPR; consent, revocable at any time |
| Provide support, prevent abuse and handle legal claims | Art. 6 (1) (b), (c) and (f) GDPR |
Where we process data on the basis of legitimate interests, we take account of data minimisation, pseudonymisation, low intensity of interference and the reasonable expectations of users. An objection is possible in accordance with Art. 21 GDPR.
4. Cookies and local storage
We use no advertising or third-party analytics cookies.
-
_sw_key: technically necessary, signed session cookie for navigation, login, CSRF protection and live functions; generally for the browser session. -
_bw_system: own, pseudonymous visitor identifier for shared sessions, participant attribution, event integrity and recognition; currently one year at most. -
_bw_locale: technically necessary cookie storing the language chosen on the website, so that visits without a language in the path appear in that language; contains nothing but the language codedeoren; one year at most. - Login cookie: only if a persistent login is chosen; signed cookie for the duration shown at the time.
- Local or session storage: may store pseudonymous session, display and campaign data.
- Cloudflare security identifiers: Cloudflare may set technically necessary identifiers to defend against bots and attacks.
Where storage or access is strictly necessary for the service expressly requested or for its secure transmission, this takes place pursuant to § 25 (2) no. 2 TDDDG. Optional analytics or marketing technologies are activated only after any required consent.
5. Recipients and service providers
Hosting and database
The application and the PostgreSQL database are hosted on server infrastructure operated by Parlant in Germany. Operators and technical service providers receive data only to the extent necessary for operation, backup and troubleshooting.
Cloudflare
Cloudflare, Inc. and affiliated companies provide DNS, TLS, DDoS protection and tunnels. This involves processing IP addresses, connection and security data in particular. Cloudflare belongs to a US corporate group. Third country transfers rely, where applicable, on the EU-US Data Privacy Framework adequacy decision and additionally on EU standard contractual clauses. Information: Cloudflare privacy.
Stripe and the payment methods offered
For the shop we use Stripe Payments Europe, Limited and the Stripe group of companies. Stripe processes contact, device, payment, fraud prevention and transaction data partly as a processor and partly as its own controller. For the German launch, credit and debit cards are offered, as well as Apple Pay and Google Pay on supported devices. PayPal and SEPA direct debit are not offered at present. Information: Stripe Privacy Center.
Shipping service providers
For shipping and tracking, Deutsche Post AG, DHL Paket GmbH and their delivery partners receive name, delivery address, shipment and contact data. Another equivalent shipping service provider is used only where necessary for the specific delivery.
Email dispatch
An SMTP service provider bound by our instructions processes recipient address, message content, dispatch time and delivery status for necessary account, order and support messages. The provider currently used can be requested at [email protected].
6. Third country transfers
Third country transfers can arise in particular through Cloudflare, Stripe and their sub-processors. Depending on the recipient, we rely on an adequacy decision under Art. 45 GDPR, in particular the EU-US Data Privacy Framework for certified recipients, or on appropriate safeguards under Art. 46 GDPR, in particular EU standard contractual clauses. Information about, or copies of, the safeguards can be requested; trade secrets may be redacted.
7. Retention periods
- Session and authentication data: until expiry, logout or deletion of the account; security-relevant evidence potentially longer, according to limitation criteria.
- Pseudonymous website events: generally twelve months at most, then deletion or aggregation, unless a specific security or legal review requires otherwise.
- Digital sessions: as long as the session is active or needed to resume it; then deletion under the operational deletion concept or on a justified request, unless obligations require otherwise.
- Orders, invoices and payments: in line with commercial and tax retention periods, regularly six, eight or ten years.
- Withdrawals, returns, complaints and legal correspondence: until conclusion and thereafter in line with statutory retention and limitation periods.
- Newsletter data: until consent is withdrawn; evidence of consent thereafter, to the extent necessary for legal defence.
- Server and security logs: only as long as necessary for operation, abuse prevention or legal claims.
Deletion is temporarily withheld where statutory retention, preservation of evidence or third-party rights require it; processing is then restricted.
8. Obligation to provide data and automated decisions
Delivery, contact, contract and payment data are required for an order. Without this data no purchase is possible. For the free app, only the technically necessary session data are required; an account is needed only for account-bound functions.
Parlant makes no solely automated decisions with legal or similarly significant effect within the meaning of Art. 22 GDPR. Stripe and payment providers may run their own automated fraud or risk checks.
9. Rights of data subjects
Under the statutory conditions, data subjects have rights of access, rectification, erasure, restriction, data portability and objection, as well as the right to withdraw consent with effect for the future. A message to [email protected] is sufficient to exercise them. We may request proof of identity where this is necessary to protect the data.
Objection: where we process data on the basis of Art. 6 (1) (f) GDPR, you may object at any time on grounds relating to your particular situation. You may object to direct marketing at any time without giving reasons.
10. Right to lodge a complaint
Data subjects can lodge a complaint with a data protection supervisory authority. The authority responsible for Parlant is in particular:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
www.datenschutz-berlin.de
11. Security and changes
We use appropriate technical and organisational measures, in particular encrypted transmission, access restrictions, backups and security updates. No internet-based service is absolutely secure.
We update this statement when processing, service providers or the legal situation change. In the event of material changes we provide information through a suitable means of contact.